Soru

Zorluk: ZorMicrosoft Entra ID Authentication and Conditional Access

An enterprise is designing a secure identity and access management infrastructure. You are tasked with mapping specific access control requirements to their corresponding Microsoft Entra ID or Conditional Access configuration. Match each requirement on the left to the most appropriate configuration on the right to satisfy the requirement.

  • Ensure that external consultants can only access corporate web apps from compliant devices or trusted locations, and force them to re-authenticate after 4 hours of inactivity.Conditional Access policy with Grant controls (Require compliant device OR Approved location) and Session controls (Sign-in frequency set to 4 hours).
  • Require administrative users to use FIDO2 security keys to manage Azure resources, and grant them high-privilege roles only for a maximum duration of 8 hours upon manager approval.Entra ID Privileged Identity Management (PIM) role activation settings combined with a Conditional Access policy enforcing phishing-resistant authentication strengths.
  • Guarantee that the tenant remains manageable if a major service outage affects Entra MFA, while ensuring any sign-in by these recovery accounts is immediately notified to security operations.Emergency access accounts excluded from all Conditional Access policies, monitored by an Azure Monitor alert rule scoped to their specific User Principal Names.
  • Detect when an employee's password has been leaked on the dark web and immediately prevent them from signing in until an administrator resets their password.Microsoft Entra ID Protection User risk policy set to block access when the risk level is High.

Cevap

Match the external consultant session timeout to the Conditional Access policy with grant and session controls; the administrative FIDO2 and PIM role activation to the PIM role settings combined with CA authentication strengths; the tenant management resilience to the emergency access accounts excluded from CA policies and monitored; and the leaked password detection to the Microsoft Entra ID Protection User risk policy.
The requirement for external consultant session limits maps to Conditional Access session controls. Enforcing phishing-resistant MFA and approval-based elevation maps to Privileged Identity Management (PIM) integrated with CA authentication strengths. Tenant resiliency during MFA outages maps to emergency access accounts excluded from CA policies. Automated blocking for leaked credentials maps to the Microsoft Entra ID Protection User risk policy.

Adım Adım Çözüm

1
Analyze requirement for external consultants.
Identified the need for conditional access based on device compliance/location and session expiration (4-hour frequency limit).
Enforcing location/compliance and a 4-hour timeout requires a Conditional Access policy using both grant and session controls.
2
Analyze requirement for developer administrative access.
Identified the need for phishing-resistant MFA (FIDO2) and approval-based, time-bound privilege activation.
FIDO2 authentication strength is enforced via Conditional Access, and temporary, approved role assignment is managed via Microsoft Entra Privileged Identity Management (PIM).
3
Analyze requirement for emergency lockout resilience.
Identified the need for emergency access (break-glass) accounts that bypass CA policies, coupled with alert monitoring.
Excluding emergency accounts from CA prevents lockout during MFA outages, and monitoring their login activity via Azure Monitor ensures security visibility.
4
Analyze requirement for dark web credential leaks.
Identified the need to block compromised users immediately.
Microsoft Entra ID Protection detects leaked credentials as high user risk, triggering the configured User risk policy to block access.

Anahtar Kavram

Microsoft Entra ID Authentication and Conditional Access
Tahmini Süre:3m 0s
Bu soruyu puanla